#TerminalServices
#100DaysOfKQL

Day 2 - RemoteInteractive Session From Service Account

One of my favorite thing to look for in IRs: if any service accounts was used for RDP (dead giveaway 99.9% of the time).

Queries for MDE, MDI and Security + TerminalServices

github.com/SecurityAura...
github.com
January 2, 2025 at 7:55 PM
Impacket tstool uses MSRPC to enumerate, control, disconnect, log off, reboot, and hijack Windows Terminal Services sessions remotely, with Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket support. #TerminalServices #MSRPC #Impacket
Impacket For Pentester: Tstool
impacket-tstool uses MSRPC to remotely enumerate, control, disconnect, log off, reboot, and even hijack Windows Terminal Services sessions without dropping a binary or opening an RDP client. It also supports passwordless authentication methods like Pass-the-Hash, Pass-the-Key, and Pass-the-Ticket, making it a stealthy post-exploitation tool against systems such as the DC1 domain controller in ignite.local. #impacket-tstool #TerminalServices #DC1 #ignite.local #tscon #qwinsta
www.hendryadrian.com
September 23, 2026 at 9:00 AM
Here are some tips on how to import from a CSV file in Royal TS 💡📂

#csv #remotedesktop #rdp #devops #itadmin #terminalservices
April 16, 2026 at 1:31 PM
Tired of Managing Multiple Remote Sessions manually? Here’s the Fix 💡 Read more under www.royalapps.com/go/help-ts-w...

#RoyalTS #SysAdminLife #RemoteDesktop #ITManagement #TerminalServices #RoyalServer
May 15, 2025 at 1:57 PM
❗️”An error occurred while loading a document” sounds familiar? 🫠 This can be fixed by giving Royal TSX Full Disk Access via the System Settings → Privacy & Security → Full Disk Access section as shown here:

#csv #remotedesktop #rdp #devops #itadmin #terminalservices
April 20, 2026 at 1:01 PM
Qilin Ransomware Unleashes Stealthy RDP Recon Tactic – How to Detect and Stop It + Video

Introduction: Recent cybersecurity observations reveal that the Qilin ransomware gang has evolved its post-compromise reconnaissance by using native PowerShell commands to silently enumerate Remote Desktop…
Qilin Ransomware Unleashes Stealthy RDP Recon Tactic – How to Detect and Stop It + Video
Introduction: Recent cybersecurity observations reveal that the Qilin ransomware gang has evolved its post-compromise reconnaissance by using native PowerShell commands to silently enumerate Remote Desktop Protocol (RDP) authentication history on compromised servers. This stealthy technique, which extracts Event ID 1149 logs from the `Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational` log to map network pivot points and identify privileged accounts, allows attackers to evade traditional detection tools while planning lateral movement.
undercodetesting.com
May 4, 2026 at 11:46 AM
Did you know that out of the box, Royal TS has the ability to send its logs to an Elasticsearch Server/Cluster? 👀 Check out our Community Page for more information ➡️ community.royalapps.com/t/how-to-sen...

#devops #itadmin #terminalservices #RDP #remotedesktop #ssh
March 2, 2026 at 3:01 PM
Tired of Managing Multiple Remote Sessions manually? Here’s the Fix 💡 Read more under: royalapps.com/go/help-ts-w...

#devops #itadmin #terminalservices #RDP #remotedesktop #ssh
February 26, 2026 at 3:21 PM
📌 Suspected Remote Access Incident on Virtual Machine Highlights Detection Challenges https://www.cyberhub.blog/article/12996-suspected-remote-access-incident-on-virtual-machine-highlights-detection-challenges
Suspected Remote Access Incident on Virtual Machine Highlights Detection Challenges
A recent report on Reddit describes a user's observation of unauthorized remote access to their virtual machine (VM). The user noticed their workstation, which was in sleep mode, turned on by itself, and someone appeared to be navigating through Excel files for approximately 15 to 30 seconds. The VM is monitored by Microsoft Defender for Endpoint, and subsequent checks of security event logs, Office 365 activity, and TerminalServices-LocalSessionManager logs revealed no suspicious activity. This incident raises important questions about the effectiveness of current detection mechanisms. Despite the use of advanced security tools like Defender for Endpoint, the user's observation suggests a potential breach that went undetected by standard monitoring tools. This could indicate the use of sophisticated evasion techniques by attackers, such as living-off-the-land binaries (LOLBins) or legitimate remote management tools, which can bypass traditional detection methods. From a technical perspective, remote access to a VM can occur through various protocols, including RDP and VNC. However, the absence of suspicious entries in the TerminalServices-LocalSessionManager logs suggests that no unauthorized RDP sessions were established. This could imply the use of alternative remote access methods or insider threats. The incident underscores the importance of comprehensive logging and monitoring. Organizations should ensure that all remote access tools and protocols are properly logged and monitored. Regular audits of security logs and continuous monitoring are essential to detect anomalies that might otherwise go unnoticed. Furthermore, this case highlights the need for a multi-layered defense strategy. While endpoint detection and response (EDR) tools like Defender for Endpoint are crucial, they should be complemented with network monitoring, user awareness training, and regular security configuration reviews to minimize blind spots. In conclusion, this suspected remote access incident serves as a reminder of the evolving tactics used by attackers to evade detection. Cybersecurity professionals must remain vigilant, continuously update their defense strategies, and ensure that all potential entry points are monitored and secured.
www.cyberhub.blog
September 10, 2025 at 8:20 PM
ICAO: #AD5D3D
Owner: #TERMINALSERVICES
Flt: #N960MD #TBM9
Time: 2026-06-04 11:09:26 CDT
Min Alt: 30000 ft
Min Dist: 126.9 nm (-125deg SW)
Squawk: #2251
#adsb #planefence by kx1t sdr-e adsbexchange flightaware faa
June 4, 2026 at 4:42 PM